Privacy Policy

Last updated 1 October 2026

This Privacy Policy explains what personal data RantWall (rantwall.app) collects, why, who we share it with, how long we keep it, and the rights you have under the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Information Technology Act, 2000 and its rules.

RantWall is run by Akshay Joshi ("we", "us"), B-104, Titanium Heights, Corporate Rd, Prahlad Nagar, Ahmedabad, Gujarat 380015. For the personal data described here, we are the Data Fiduciary.

The short version

  • Other users never see who wrote an anonymous rant. We can, and so can a lawful order.
  • We keep as little as we can: a way to log you in, your username and the settings you pick. No real name, no photo, no contacts, no precise location.
  • Your mobile number is stored encrypted. We don't store IP addresses, only keyed hashes of them.
  • No ads, no advertising or analytics trackers, and we don't sell your data.
  • Delete your account in Settings and your rants, reactions and login details go with it.

What we collect

When you create and use an account:

  • Mobile number, if you sign in by phone: stored encrypted, together with a keyed hash (to find your account when you log in) and its last 2 digits (so we can show it to you as "+91 ••••••••42"). We generate the one-time codes ourselves; they expire after 10 minutes.
  • Email address, if you sign up or log in with email, and whether you have verified it. If you set a password we store only a secure hash of it.
  • Google, if you choose Sign in with Google: your Google account ID and verified email address. Google also sends your name and photo; we delete them before saving anything, so they are never stored.
  • Profile: your username, your language, an optional bio of up to 160 characters and a sticker avatar from our set. There are no profile photos.
  • The version of the Terms you accepted, with your confirmation that you are 18 or older, and when you accepted.

When you post and use RantWall:

  • Rants: the text, the channels you pick, whether the rant is anonymous (with its random handle) and, in Client Horror, the optional industry, project type and unpaid amount you add. For an anonymous rant we still record which account posted it.
  • Reactions and saves: which rants you reacted to or saved. Counts are public; who reacted or saved is not shown to other users, and your saved list is visible only to you.
  • Views and shares: we count them per rant. To count each person once we use short-lived keys that expire within a day for views and two days for shares; we don't keep a history of what you viewed.
  • Reports you file (the reason and any note), people or rants you block, and the private notices we send you about your rants and badges.
  • Moderation records: the result of the automated checks on your rants, username and bio, and what moderators decided.

Technical data:

  • IP address: we use it when your request arrives, to apply rate limits and sign-up limits and to stop abuse. We don't store it. Where we need to remember it, we keep only a keyed hash (HMAC) of your IP address or network, which can't be turned back into the address.
  • A log of writes: for each sign-up, rant and block we keep the time, the account and the IP hash, for 180 days (see "How long we keep it").
  • Country: when our network provider tells us which country a request comes from, we use it only to pick your default language, and we don't store it.
  • Error reports: when something breaks, technical details go to our error-monitoring service with cookies, headers, query strings, request bodies and user details removed.

We don't collect your real name, photos of you, your contacts, your precise location or payment details.

Why we use it

  • To create and secure your account and log you in, and to send the texts and emails that needs: one-time codes, email verification and password resets. We don't send marketing messages.
  • To publish your rants and show reactions, views, saves, shares, karma and badges.
  • To moderate: to check rants, usernames and bios before they appear, act on reports, and keep people safe, including showing the Tele-MANAS helpline when a rant suggests someone may be in distress.
  • To prevent abuse: rate limits, bot checks, bans and fraud prevention.
  • To meet legal duties: to respond to complaints and lawful orders and keep the records the law requires.

We process your data on the basis of the consent you give when you enter RantWall and create an account, and for the legitimate uses the DPDP Act allows, such as complying with the law and with court orders.

Who can see what

  • Everyone, including people without an account and search engines: your username, sticker, bio, your named rants, and your public karma, streak and badges.
  • An anonymous rant shows only a random handle. It never shows your username, sticker or account, never appears on your profile, and never counts toward your public stats or badges.
  • Moderators review content without seeing who posted it.
  • A few authorised staff can see the account behind a rant (its username, email address, joining date and status) when it's needed for moderation, safety or a legal requirement. They must write down a reason first, and every such look is recorded in our audit log. Seeing a mobile number in full needs a separate permission and is logged the same way.
  • Authorities: we disclose information, which can include the account behind an anonymous rant, when a court or an authorised government agency lawfully requires it.

In short: anonymous to other users, not to RantWall or to a lawful order.

Who we share it with

We don't sell your data or share it for advertising. These service providers process data for us, only to run RantWall:

Amazon Web Services (AWS)
Hosting and AI moderation. Our servers, database and backups run on AWS in Mumbai, India. Before a rant, username, bio or Client Horror project field is published, its text is sent to an AI model (the open-weight gpt-oss-120b) that AWS runs for us on Amazon Bedrock, for an automated check. Nothing else about you (no account, email address, number or IP address) is sent with it. The check runs in India where AWS offers the model there, otherwise in the United States.
MSG91
Sends the one-time codes for phone sign-in. Receives your mobile number and the code.
Our email provider
Sends login codes, verification and password-reset emails. Receives your email address and the message.
Google
Only if you choose Sign in with Google: confirms who you are and tells us your Google account ID and verified email.
Cloudflare
Runs our bot checks (Turnstile) on sign-up, log-in, posting, reports and blocks, and receives your IP address and browser signals to do so. It may also carry our traffic as our network and security provider.
Sentry
Error monitoring, with personal data removed as described above.

Some of these providers process data outside India, including in the United States. The DPDP Act allows this except to countries the Government of India restricts.

We also share information when the law requires it, as described above, and could transfer it to a successor if RantWall is sold or reorganised, under this policy.

Cookies and storage on your device

We use only cookies RantWall needs to work. There are no advertising or analytics cookies and no third-party trackers.

sessionid
Keeps you logged in, for up to two weeks or until you log out.
csrftoken
Protects forms against cross-site request forgery.
lang, lang_auto, lang_banner
Your language, whether it was picked from your region, and whether you closed the language banner. One year.
entry_ok
Remembers that you confirmed you are 18+ and accepted the Terms and Rules at the entry screen. One year.
vid
A random, signed visitor ID so each view and share is counted once. It contains nothing about you. One year.

Your browser also keeps a few settings on your device only: whether you last posted anonymously or under your name, when you last opened the badges page, and, briefly, the username you are deleting while you sign in again with Google. Our network provider may set its own strictly necessary security cookies.

How long we keep it

  • Your account, rants, reactions, saves, reports, blocks and notices: until you delete your account.
  • Rants that moderators reject or remove stay in our records, hidden from everyone else, until the account is deleted, so we can handle complaints, reviews and legal requests.
  • The write log (time, account and IP hash of sign-ups, rants and blocks): 180 days, then deleted automatically every night.
  • Phone sign-ups whose code was never confirmed: deleted after about a day.
  • Expired login sessions: cleared every night.
  • The audit log of staff actions: kept as a lasting record. It names the rant or account acted on, never your mobile number.
  • We may keep specific data longer when a court or authority lawfully asks us to preserve it.

Deleting your account

Go to Settings, then Account, then delete your account. You sign in again, type your username and confirm. This can't be undone. It removes:

  • your username (then locked for 30 days so nobody can pose as you), bio and sticker;
  • all your rants, anonymous ones included, and your badges;
  • your reactions and saves (the counts on other people's rants are recalculated), your reports, your blocks and your notices;
  • your email address, mobile number and Google connection.

What stays: the write log, whose rows keep only the IP hash and a one-way marker of the deleted account (so a legal request about that account can still be matched) until their 180 days are up, and staff audit-log entries about actions taken. Share cards that people already saved or sent outside RantWall are beyond our reach.

Your rights

Under the DPDP Act you can:

  • Get a summary of your data: ask us for a summary of the personal data we hold about you, how we use it, and who we have shared it with. Your profile, rants and settings are also visible to you in the app.
  • Correct and update it: change your bio, sticker, language and mobile number in Settings. For anything else, such as your email address or username, write to us.
  • Erase it: delete your account in Settings, as described above. You can't yet delete a single rant yourself; you can turn a named rant anonymous from its menu, or ask us to remove it.
  • Withdraw consent: at any time, by deleting your account. This doesn't affect what we did before, or what we must keep by law.
  • Nominate someone: name a person who can use these rights for you if you die or can't act yourself, by writing to our Grievance Officer with their details.
  • Complain: to our Grievance Officer first, and if you are not satisfied, to the Data Protection Board of India.

To use any of these rights, email our Grievance Officer at grievance@rantwall.app. We may ask you to show that the account is yours before we act. See the Grievance Redressal page for timelines.

You also have duties under the DPDP Act: don't impersonate anyone, don't hide important information when giving us your details, and don't file false or frivolous complaints.

Adults only

RantWall is only for people aged 18 or older, and we don't knowingly collect data from anyone younger. If you believe a child is using RantWall, tell us at grievance@rantwall.app and we will act on it.

How we protect it

Connections to RantWall are encrypted (HTTPS). Mobile numbers are encrypted in our database, passwords are stored only as secure hashes, and IP addresses are kept only as keyed hashes. Staff tools are permission-controlled, and looking up who wrote a rant or a full mobile number is logged. No system is perfectly secure; if a breach affects your personal data, we will inform you and the Data Protection Board as the law requires.

Changes to this policy

We may update this policy. When we do, we change the "Last updated" date above, and for significant changes we will give notice on RantWall.

Contact

Data Fiduciary
Akshay Joshi, B-104, Titanium Heights, Corporate Rd, Prahlad Nagar, Ahmedabad, Gujarat 380015
Grievance Officer
Akshay Joshi, grievance@rantwall.app
General contact
hello@rantwall.app

The content you must not post is listed in our Terms and Community Rules; that list is part of this policy too.